← Back
CWE-287

4,511 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,511)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Guacamole
Jun 17, 2026
Jan 11, 2022
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allow a malicious user to assume the identity of another Guacamole user.
1Mirantis
1Lens
Jun 17, 2026
Jan 10, 2022
N/A· v4
9.6 CRITICAL· v3
5.1 MEDIUM· v2
Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website. The malicious website could make websocket connections from the victim's browser to Lens and so operate the local terminal...Show more
Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website. The malicious website could make websocket connections from the victim's browser to Lens and so operate the local terminal feature. This would allow the attacker to execute arbitrary commands as the Lens user.Show less
1Samsung
1S Assistant
Jun 17, 2026
Jan 10, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive information.
1Samsung
1Internet
Jun 17, 2026
Jan 10, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode password authentication
1Samsung
1Health
Jun 17, 2026
Jan 10, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Improper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out from Samsung Health App.
1Starwind
2Command Center
San&nas
Jun 17, 2026
Jan 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the authentication process, thus could escalate privileges. This affects StarWind SAN and NAS build 1578 a...Show more
A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the authentication process, thus could escalate privileges. This affects StarWind SAN and NAS build 1578 and StarWind Command Center build 6864.Show less
1Sun Moon Jingyao
1Network Computer Terminal Protection System Firmware
Jun 17, 2026
Jan 3, 2022
N/A· v4
9.0 CRITICAL· v3
7.7 HIGH· v2
The server-request receiver function of Shockwall system has an improper authentication vulnerability. An authenticated attacker of an agent computer within the local area network can use the local registry information t...Show more
The server-request receiver function of Shockwall system has an improper authentication vulnerability. An authenticated attacker of an agent computer within the local area network can use the local registry information to launch server-side request forgery (SSRF) attack on another agent computer, resulting in arbitrary code execution for controlling the system or disrupting service.Show less
1Netgear
1R6700 Firmware
Jun 17, 2026
Dec 30, 2021
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection and ex...Show more
Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection and execute commands as the root user without authentication.Show less
1Netgear
1Rax43 Firmware
Jun 17, 2026
Dec 30, 2021
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
Netgear RAX43 version 1.0.3.96 does not have sufficient protections to the UART interface. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection, login with defa...Show more
Netgear RAX43 version 1.0.3.96 does not have sufficient protections to the UART interface. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection, login with default credentials, and execute commands as the root user. These default credentials are admin:admin.Show less
1Trendnet
1Tew 827dru Firmware
Jun 17, 2026
Dec 30, 2021
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient protections for the UART functionality. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection...Show more
Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient protections for the UART functionality. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection. No username or password is required and the user is given a root shell with full control of the device.Show less
1Glewlwyd Project
1Glewlwyd
Jun 17, 2026
Dec 30, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Glewlwyd 2.0.0, fixed in 2.6.1 is affected by an incorrect access control vulnerability. One user can attempt to log in as another user without its password.
1Qnap
1Qfile
Jun 17, 2026
Dec 29, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An improper authentication vulnerability has been reported to affect Android App Qfile. If exploited, this vulnerability allows attackers to compromise app and access information We have already fixed this vulnerability...Show more
An improper authentication vulnerability has been reported to affect Android App Qfile. If exploited, this vulnerability allows attackers to compromise app and access information We have already fixed this vulnerability in the following versions of Qfile: Qfile 3.0.0.1105 and laterShow less
1Authguard Project
1Authguard
Jun 17, 2026
Dec 27, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
basic/BasicAuthProvider.java in AuthGuard before 0.9.0 allows authentication via an inactive identifier.
1Anker
1Eufy Homebase 2 Firmware
Jun 17, 2026
Dec 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to incr...Show more
An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to increased privileges.Show less
1Garrett
1Ic Module Cma
Jun 17, 2026
Dec 22, 2021
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
An authentication bypass vulnerability exists in the CMA run_server_6877 functionality of Garrett Metal Detectors iC Module CMA Version 5.0. A properly-timed network connection can lead to authentication bypass via sessi...Show more
An authentication bypass vulnerability exists in the CMA run_server_6877 functionality of Garrett Metal Detectors iC Module CMA Version 5.0. A properly-timed network connection can lead to authentication bypass via session hijacking. An attacker can send a sequence of requests to trigger this vulnerability.Show less
1Mesalabs
1Amegaview
Jun 17, 2026
Dec 21, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Mesa Labs AmegaView Versions 3.0 and prior’s passcode is generated by an easily reversible algorithm, which may allow an attacker to gain access to the device.
1Dell
1Powerscale Onefs
Jun 17, 2026
Dec 21, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Dell PowerScale OneFS, versions 8.2.2-9.3.0.x, contain an authentication bypass by primary weakness in one of the authentication factors. A remote unauthenticated attacker may potentially exploit this vulnerability and b...Show more
Dell PowerScale OneFS, versions 8.2.2-9.3.0.x, contain an authentication bypass by primary weakness in one of the authentication factors. A remote unauthenticated attacker may potentially exploit this vulnerability and bypass one of the factors of authentication.Show less
1Zohocorp
1Manageengine Pam360
Jun 17, 2026
Dec 20, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authentication is not required.
1Zohocorp
1Manageengine Access Manager Plus
Jun 17, 2026
Dec 20, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects of the application state.
1Zohocorp
1Manageengine Servicedesk Plus Msp
Jun 17, 2026
Dec 20, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which authentication is not required.